Since its public introduction in the mid-2010s, the Row Hammer (RH) phenomenon has drawn significant attention from the research community due to its security implications. Although many RH-protection schemes have been proposed by processor vendors, DRAM manufacturers, and academia, they still have shortcomings. Solutions implemented in the memory controller (MC) pay an increasingly higher cost due to their conservative design for the worst case in terms of the number of DRAM banks and RH threshold to support. Meanwhile, the DRAM-side implementation has a limited time margin for RH protection measures or requires extensive modifications to the standard DRAM interface. Recently, a new command for RH protection has been introduced in the DDR5/LPDDR5 standards, called refresh management (RFM). RFM enables the separation of the tasks for RH protection to both MC and DRAM. It does so by having the former generate an RFM command at a specific activation frequency, and the latter take proper RH protection measures within a given time window. Although promising, no existing study presents and analyzes RFM-based solutions for RH protection. In this paper, we propose Mithril, the first RFM interface-compatible, DRAM-MC cooperative RH protection scheme providing deterministic protection guarantees. Mithril has minimal energy overheads for common use cases without adversarial memory access patterns. We also introduce Mithril+, an extension to provide minimal performance overheads at the expense of a tiny modification to the MC while utilizing an existing DRAM command.
翻译:自2010年代中期公开推行以来,Row Hammer(RH)现象因其安全影响而引起研究界的极大关注,尽管加工商供应商、DRAM制造商和学术界已提出许多生殖健康保护计划,但它们仍然有缺陷;记忆控制公司(MC)实施的解决办法,由于在DRAM银行数量和需要支持的RH门槛方面,其最差情况的保守设计费用越来越高;同时,DRAM方面的执行,在生殖健康保护措施方面有有限的时间余地,或需要对DRAM标准接口进行广泛的修改;最近,在DDDR5/LPDDD5标准中引入了新的生殖健康保护指令,称为 " 更新管理 " (RFMM),使得将生殖健康保护的任务分开给MC和DRAM两个机构,而通过将RFM的指令在特定启动频率上产生适当的最差设计,而后者在特定时间窗口内采取适当的生殖健康保护措施;尽管目前没有进行的研究显示和分析基于RMFM的解决方案,但需要对RRM的解决方案进行广泛的利用。